Cathedral affected by cyber attack
BBCA software company which stores contact details of supporters of Lincoln Cathedral and leisure centre users in Lincolnshire says it has experienced a "cyber-security incident".
Beacon CRM said the incident involved unauthorised access to systems containing data it processes on behalf of its customers.
Lincoln Cathedral and Magna Vitae said they used Beacon to store data including names, addresses, emails, and phone numbers, but not payment or bank account details.
Beacon CRM said: "We immediately engaged external cyber-security experts to help us contain the incident and investigate."
The software is used by more than 1,000 charities and organisations.
Beacon CRM said: "We understand this is concerning and we're taking it very seriously. We've already spoken with all our customers and our focus now is on supporting them as much as possible in any onward communication of their own regarding potential data impact.
"Beyond our immediate containment actions, Beacon hasn't experienced any service interruption as a result of this incident and our customers continue to access our platform and services as normal."
Dino Panato/Getty ImagesA spokesperson for Lincoln Cathedral said Beacon informed them it had "identified unauthorised access to its systems" on Monday 3 August.
It said there was no evidence any data had been published online, or that a ransom demand had been made.
The Very Reverend Dr Simon Jones, Dean of Lincoln, said: "While this cyber incident occurred within a third-party system rather than the Cathedral's own IT infrastructure, we take our responsibilities for protecting personal information extremely seriously.
"We are working closely with Beacon as they continue their investigation and have taken the appropriate steps to report the incident and safeguard the information entrusted to us."
In an email to users, Magna Vitae, which operates leisure centres in Skegness, Horncastle, Mablethorpe and Louth, said the information stored "varies by person" and may also include event attendance, SO Festival engagement records, or equality, diversity and inclusion information.
It said there was no evidence data had been published or shared elsewhere, but urged people to be cautious of suspicious messages, links or attachments.
Both organisations said they had reported the incident to the Information Commissioner's Office (ICO) as a data breach.
The ICO said: "We are aware of an incident at Beacon CRM and have received a number of reports from impacted organisations. We are assessing the information provided and are in contact with Beacon Apps Ltd.
"Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people's rights and freedoms."
Listen to highlights fromLincolnshire on BBC Sounds, watch thelatest episode of Look North.
Download the BBC News app from the App Storefor iPhone and iPad orGoogle Play for Android devices
